US11343230B2 - Method for configuring device resources based on network identification and system therefor - Google Patents
Method for configuring device resources based on network identification and system therefor Download PDFInfo
- Publication number
- US11343230B2 US11343230B2 US16/896,626 US202016896626A US11343230B2 US 11343230 B2 US11343230 B2 US 11343230B2 US 202016896626 A US202016896626 A US 202016896626A US 11343230 B2 US11343230 B2 US 11343230B2
- Authority
- US
- United States
- Prior art keywords
- information handling
- handling system
- address
- wan
- trusted
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/0227—Filtering policies
- H04L63/0236—Filtering by address, protocol, port number or service, e.g. IP-address or URL
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/101—Access control lists [ACL]
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/44—Arrangements for executing specific programs
- G06F9/4401—Bootstrapping
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/44—Arrangements for executing specific programs
- G06F9/4401—Bootstrapping
- G06F9/4416—Network booting; Remote initial program loading [RIPL]
-
- H04L61/2007—
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/50—Address allocation
- H04L61/5007—Internet protocol [IP] addresses
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F8/00—Arrangements for software engineering
- G06F8/60—Software deployment
- G06F8/65—Updates
- G06F8/654—Updates using techniques specially adapted for alterable solid state memories, e.g. for EEPROM or flash memories
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L61/00—Network arrangements, protocols or services for addressing or naming
- H04L61/35—Network arrangements, protocols or services for addressing or naming involving non-standard use of addresses for implementing network functionalities, e.g. coding subscription information within the address or functional addressing, i.e. assigning an address to a function
Definitions
- This disclosure generally relates to information handling systems, and more particularly relates to configuring device resources based on network identification.
- An information handling system generally processes, compiles, stores, and/or communicates information or data for business, personal, or other purposes. Because technology and information handling needs and requirements may vary between different applications, information handling systems may also vary regarding what information is handled, how the information is handled, how much information is processed, stored, or communicated, and how quickly and efficiently the information may be processed, stored, or communicated. The variations in information handling systems allow for information handling systems to be general or configured for a specific user or specific use such as financial transaction processing, reservations, enterprise data storage, or global communications. In addition, information handling systems may include a variety of hardware and software resources that may be configured to process, store, and communicate information and may include one or more computer systems, data storage systems, and networking systems.
- a method for configuring resources at an information handling system may include determining, during initialization, a wide area network (WAN) Internet Protocol (IP) address associated with the information handling system, and retrieving a list of trusted IP addresses from a storage location at the information handling system.
- the method may further include configuring a first resource at the information handling system to operate in a first state in response to determining that the WAN IP address is included at the list of trusted IP addresses, and configuring the first resource at the information handling system to operate in a second state in response to determining that the WAN IP address is not included at the list of trusted IP addresses.
- WAN wide area network
- IP Internet Protocol
- FIG. 1 is a block diagram of an information handling system according to a specific embodiment of the present disclosure
- FIG. 2 is a block diagram illustrating a system for configuring device resources based on network identification according to a specific embodiment of the present disclosure.
- FIG. 3 is a flow diagram illustrating a method for configuring device resources based on network identification, according to a specific embodiment of the present disclosure.
- FIG. 1 illustrates an information handling system 100 including a processor 102 , a memory 104 , a chipset 106 , a Peripheral Component Interconnect (PCI) bus 108 , a Universal Serial Bus (USB) controller 110 , a USB 112 , a keyboard device 114 , a mouse device controller 116 , an Advanced Technology Attachment (ATA) bus controller 120 , an ATA bus 122 , a data storage device 124 , a compact disk read only memory (CD ROM) device 126 , a video graphics array (VGA) device 130 , a display device 131 , a network interface controller (MC) 140 , a wireless local area network (WLAN) controller 150 , one or more serial busses 160 , a non-volatile rand access memory (NVRAM) 170 for storing a basic input/output system (BIOS) 172 , a Trusted Platform Module (TPM) 180 , and an embedded controller (EC) 190 .
- NVRAM 170 can be referred to as a serial peripheral interface (SPI) flash storage device, BIOS SPI, and the like.
- TPM 180 is configured to ensure that the boot process starts from a trusted combination of hardware and software, and continues until the operating system has fully booted and applications are running.
- TPM 180 is compliant with an international standard for a secure cryptoprocessor, a dedicated microcontroller designed to secure hardware through integrated cryptographic keys.
- EC 190 can be referred to as a service processor, a baseboard management controller (BMC), and the like.
- EC 190 includes a processor that can operate out-of-band with respect to CPU 102 .
- remote management systems can utilize EC 190 to access components at information handling system independent of an operating state of CPU 102 .
- EC 190 may be responsible for performing low level hardware tasks including thermal management and power management operations.
- Information handling system 100 can include additional components and additional busses, not shown for clarity.
- system 100 can include multiple processor cores, audio devices, and the like. While a particular arrangement of bus technologies and interconnections is illustrated for the purpose of example, one of skill will appreciate that the techniques disclosed herein are applicable to other system architectures.
- System 100 can include multiple CPUs and one ore more components can be integrated together. For example, portions of chipset 106 can be integrated within CPU 102 . In an embodiment, chipset 106 can include a platform controller hub (PCH).
- PCH platform controller hub
- System 100 can include additional buses and bus protocols.
- Serial bus 160 is representative of one or more busses and/or bus protocols, such as a serial peripheral interface (SPI) bus, an inter-integrated circuit protocol (I2C) bus, a system management bus (SMB), a power management bus (PMBus), and the like.
- Additional components of information handling system 100 can include one or more storage devices that can store machine-executable code, one or more communications ports for communicating with external devices, and various input and output (I/O) devices, such as a keyboard, a mouse, and a video display.
- I/O input and output
- information handling system 100 can include any instrumentality or aggregate of instrumentalities operable to compute, classify, process, transmit, receive, retrieve, originate, switch, store, display, manifest, detect, record, reproduce, handle, or utilize any form of information, intelligence, or data for business, scientific, control, entertainment, or other purposes.
- information handling system 100 can be a personal computer, a laptop computer, a smart phone, a tablet device or other consumer electronic device, a network server, a network storage device, a switch, a router, or another network communication device, or any other suitable device and may vary in size, shape, performance, functionality, and price.
- information handling system 100 can include processing resources for executing machine-executable code, such as CPU 102 , a programmable logic array (PLA), an embedded device such as a System-on-a-Chip (SoC), or other control logic hardware.
- Information handling system 100 can also include one or more computer-readable medium for storing machine-executable code, such as software or data.
- BIOS 172 includes instructions executable by CPU 102 to initialize and test the hardware components of system 100 , and to load a boot loader or an operating system (OS) from a mass storage device. BIOS 172 additionally provides an abstraction layer for the hardware, that is a consistent way for application programs and OS to interact with the keyboard, display, and other input/output devices.
- OS operating system
- BIOS 172 When power is first applied to information handling system 100 , the system begins a sequence of initialization procedures. During the initialization sequence, also referred to as a boot sequence, components of system 100 are configured and enabled for operation, and device drivers can be installed. Device drivers provide an interface through which other components of the system 100 can communicate with a corresponding device.
- BIOS 172 can provide one or more runtime processes or device drivers that are configured to support functionality disclosed herein. After the initialization procedure is complete and an operating system is loaded, such as Windows, computational operation of information handling system can begin. In an embodiment, the BIOS 172 can be substantially compliant with one or more revisions of the Unified Extensible Firmware Interface (UEFI) specification.
- UEFI Unified Extensible Firmware Interface
- Information handling systems such as personal computers, smart phones, and the like are increasingly being used to provide services that require considerable security.
- Passwords, tokens, and other authentication techniques are commonly used to verify the user's credentials before permitting access to sensitive information.
- many of these techniques are utilized after the device is initialized, for example after an operating system is activated.
- Techniques disclosed herein provide additional security measures that can be enabled during initialization, prior to when the device is fully operational.
- various system interfaces, resources, and services can be fully or partially disabled based on how the device is connected to a communication network, such as the Internet.
- information handling system 100 can be configured to have one set of capabilities when booting in trusted locations, while having a subset of those capabilities when booting in secondary locations.
- FIG. 2 shows a system 200 for configuring device resources based on network identification according to a specific embodiment of the present disclosure.
- System 200 includes BIOS 172 , NIC 140 , WLAN 150 , EC 190 , an Intel Management Engine (ME) 192 , a trusted IP list 202 , a device interface control policy 204 , and a representation of device resources and services 210 .
- BIOS 172 is responsible for initializing information handling system 100 . The initialization process is typically described as a sequence of stages, for example a Security (SEC) phase, a Pre-EFI (PEI) phase, a Driver Execution Environment (DXE) phase, a Boot Device Selection (BDS) phase, and a Transient System Load (TSL) phase.
- SEC Security
- PEI Pre-EFI
- DXE Driver Execution Environment
- BDS Boot Device Selection
- TSL Transient System Load
- Initialization completes by handing control of the information handling system to an operating system, known as Runtime.
- the DXE phase is responsible for discovering and executing DXE drivers to initialize platform components. After drivers have been dispatched, control is passed to the BDS phase of execution.
- the BDS phase is responsible for initializing console drivers, loading device drivers, and attempting to load and execute boot selections.
- the BDS phase is also responsible for implementing a platform boot policy, which can be used by system vendors to customize the user experience. In an embodiment, the techniques described below can be implemented during the BDS phase.
- BIOS 172 can determine network connectivity provided by network interface devices, such as NIC 140 , WLAN 150 , USB 110 , and the like.
- network interface devices such as NIC 140 , WLAN 150 , USB 110 , and the like.
- NIC 140 and WLAN 150 may connect via a wired or wireless Ethernet protocol to a broadband modem, a residential gateway, a router, and the like, which can provide an interface to a wide area network (WAN).
- WAN wide area network
- ISP Internet Service Provider
- the WAN assigns an Internet Protocol (IP) address to each information handling system attached to the WAN, referred to herein as a WAN IP.
- IP Internet Protocol
- an information handling system at a home or office typically connects to a WAN, including the Internet, through a specific collection of network interface devices, and as such, is assigned a substantially consistent, and trusted, WAN IP. If a user connects their device to a WAN outside of the home or office, such as via a public wireless Internet service such as WiFi, the device will be recognized on the WAN by another WAN IP. In many cases, the network can be insecure. Accordingly, system 200 is configured to recognize when information handling system 100 is not connected to a trusted network and take remedial actions as defined at interface control policy 204 .
- BIOS 172 can determine whether the WAN IP address is included in trusted IP list 202 .
- trusted IP list 202 can be stored at a location included at NVRAM 170 known as a UEFI store, which is configured to store system variables and other data. Information stored at the UEFI store can be persistent, meaning the information is maintained while information handling system 100 is powered-off. If BIOS 172 determines that the identified WAN IP address is not included at trusted IP list 202 , device interface control policy 204 can be accessed to determine how to configure selected system resources.
- one or more system interfaces or services may be restricted or fully disabled if the identified WAN IP address is not included at trusted IP list 202 .
- Policy 204 can be stored at NVRAM 170 , EC 190 , or elsewhere.
- Trusted IP list 202 and device interface policy 204 can be installed by a system administrator, an information technology (IT) specialist, an original equipment manufacturer (OEM), and the like.
- Device resources and services 210 represents one or more components or services that are typically provided at information handling system 100 .
- Examples of such components and service may include a USB type-C controller, a network interface controllers, BIOS update or network boot services, power controllers, data storage devices, and the like.
- Resources and services 210 can include any or all system features that may expose the system to unnecessary security risk.
- a USB-C device may be configured to connect information handling system 100 to a docking station, and policy 204 can specify that such connectivity should be disabled if system 100 is not coupled to a trusted WAN IP.
- policy 204 can specify alternative configurations for a device based on the specific WAN IP address or network connectivity information that is detected by BIOS 172 , and may identify additional actions to be administered based on the identified WAN IP. For example, policy 204 can specify that BIOS 172 send messages to EC 190 , ME 192 , and the like, which can take further action to restrict selected services and resources. In a particular embodiment, EC 190 can disable power delivery to specific devices or subsystems.
- BIOS 172 can alert ME 192 that system 100 is connected to an untrusted network.
- ME 192 can be configured to provide various root-of-trust activities during initialization of system 100 , and may continue to perform security, network transport, and other system operations during runtime.
- ME 192 can include access to network stack information, and thereby take part in implementation of policy 204 .
- policy 204 can mandate that system 100 only boot to a Preboot Execution Environment (PXE), which is a client-server environment that boots a software assembly retrieved from a network.
- PXE Preboot Execution Environment
- Remedial actions performed by BIOS 172 may not be visible to a user of information handling system 100 . For example, BIOS 172 may initiate a network alert action with or without disrupting a user of system 100 .
- System 200 may further be configured to adjust or override actions specified by policy 204 in response to receiving a waiver from authenticated security administrators.
- a user may request to override actions specified by policy 204 before connecting to an untrusted network, or receive override permission from an IT service in response to a request by a user of system 100 after BIOS 172 has performed remediation specified by policy 204 .
- the policy 204 can be utilized to facilitate asset detection and recovery services in the case of theft of system 100 .
- FIG. 3 shows a method 300 for configuring device resources based on network identification, according to a specific embodiment of the present disclosure.
- Method 300 begins at block 301 where a device is turned on. For example, in response to a power-on-reset, information handling system 100 begins an initialization procedure administered by BIOS 172 .
- BIOS 172 identifies network interfaces available at system 100 . For example, BIOS 172 can identify whether NIC 140 , WLAN 150 , or another device at system 100 is connected to a wide area network.
- BIOS 172 can attempt to determine a WAN IP address associated with one or more active network interfaces.
- Method 300 proceeds to decision block 304 where BIOS 172 determines whether a network IP address has been identified. If no IP address is found, method 300 proceeds to block 310 where an interface control policy is retrieved to identify remedial actions that should be invoked. If an IP address is identified at block 304 , the method proceeds to decision block 305 where BIOS 172 can determine whether the identified IP address is a local IP address or a WAN IP address. As used herein, a local IP address typically has a value of 192.168.x.x, and is associated with a local area network. If the identified IP address is not a local IP address, method 300 proceeds to block 307 where a trusted IP list is retrieved.
- method 300 proceeds to block 306 where trace-route command can be used to discover how system 100 is connected to a WAN, typically the Internet.
- a trace-rout command is a diagnostic command that identifies a network path (route) and transit delays of data packets as they propagate across a WAN to a specified destination address. Based on the information returned by the trace-route command, BIOS 172 can determine one or more network IP addresses encountered during execution of the command. After completing the trace-route procedure, method 300 continues to block 307 , where trusted IP list 202 is retrieved.
- method 300 continues to decision block 308 where BIOS 172 can determine whether the IP address identified in the preceding blocks is included in trusted IP list 202 , thereby determining whether system 100 is connected to a trusted network. If the identified IP address is included at list 202 , method 300 proceeds to block 309 where BIOS 172 continues to initialize system 100 , ultimately booting to an operating system such as Windows. Returning to decision block 308 , if BIOS 172 determines that the IP address is not included at trusted IP list 202 , method 300 proceeds to block 310 where interface control policy 204 is retrieved. At block 311 , resources specified by policy 204 are configured as defined in the policy based on the WAN IP address identified earlier in method 300 . After the policy has been enforced, method 300 proceeds to block 309 where BIOS 172 completes initialization of system 100 and transfers control to an operating system.
- policy 204 can define how to configure each of one or more enumerated system resources based on determining that system 100 is not connected to a WAN using a trusted IP address identified in trusted IP list 202 .
- Devices and services can be fully disabled or partially disabled, as specified by policy 204 . For example, if information handling system 100 is booted while connected to a WAN using a trusted IP address, all or most system resources may be fully enabled. If system 100 is booted while connected to an untrusted IP address, configuration of a specified list of devices and/or services can be modified as needed to maintain security of system 100 . If system 100 is booted while not connected to any network, yet another configuration of system resources can be selected.
- policy 204 can define particular configuration settings to utilize when a specific un-trusted WAN IP address is detected. For example, policy 204 can allow system 100 to be fully functional while operating in a secure location identified by a trusted IP address included at list 202 , while functionality may be limited when operating at a less secure location having another IP address specified at policy 204 , such as at a user's home. Yet another level of functionality may be specified by policy 204 when system 100 is operating while not connected to any network.
- list 202 can specify un-trusted IP addresses, and policy 204 can specify how to configure resources if the detected IP address is included at list 202 .
- the information handling system 100 can include a set of instructions that can be executed to cause the information handling system to perform any one or more of the methods or computer based functions disclosed herein.
- the information handling system 100 may operate as a standalone device or may be connected to other computer systems or peripheral devices, such as by a network.
- the information handling system 100 may operate in the capacity of a server or as a client user computer in a server-client user network environment, or as a peer computer system in a peer-to-peer (or distributed) network environment.
- the information handling system 100 can also be implemented as or incorporated into various devices, such as a personal computer (PC), a tablet PC, a set-top box (STB), a personal digital assistant (PDA), a mobile device, a palmtop computer, a laptop computer, a desktop computer, a communications device, a wireless telephone, a land-line telephone, a control system, a camera, a scanner, a facsimile machine, a printer, a pager, a personal trusted device, a web appliance, a network router, switch or bridge, or any other machine capable of executing a set of instructions (sequential or otherwise) that specify actions to be taken by that machine.
- the computer system 100 can be implemented using electronic devices that provide voice, video or data communication.
- the term “system” shall also be taken to include any collection of systems or sub-systems that individually or jointly execute a set, or multiple sets, of instructions to perform one or more computer functions.
- the information handling system 100 can include a disk drive unit and may include a computer-readable medium, not shown in FIG. 1 , in which one or more sets of instructions, such as software, can be embedded. Further, the instructions may embody one or more of the methods or logic as described herein. In a particular embodiment, the instructions may reside completely, or at least partially, within system memory 104 or another memory included at system 100 , and/or within the processor 102 during execution by the information handling system 100 . The system memory 104 and the processor 102 also may include computer-readable media.
- a network interface device (not shown at FIG. 1 ) can provide connectivity to a network, such as a wide area network (WAN), a local area network (LAN), or other network.
- dedicated hardware implementations such as application specific integrated circuits, programmable logic arrays and other hardware devices can be constructed to implement one or more of the methods described herein.
- Applications that may include the apparatus and systems of various embodiments can broadly include a variety of electronic and computer systems.
- One or more embodiments described herein may implement functions using two or more specific interconnected hardware modules or devices with related control and data signals that can be communicated between and through the modules, or as portions of an application-specific integrated circuit. Accordingly, the present system encompasses software, firmware, and hardware implementations.
- the methods described herein may be implemented by software programs executable by a computer system.
- implementations can include distributed processing, component/object distributed processing, and parallel processing.
- virtual computer system processing can be constructed to implement one or more of the methods or functionality as described herein.
- the present disclosure contemplates a computer-readable medium that includes instructions or receives and executes instructions responsive to a propagated signal; so that a device connected to a network can communicate voice, video or data over the network. Further, the instructions may be transmitted or received over the network via the network interface device.
- While the computer-readable medium is shown to be a single medium, the term “computer-readable medium” includes a single medium or multiple media, such as a centralized or distributed database, and/or associated caches and servers that store one or more sets of instructions.
- the term “computer-readable medium” shall also include any medium that is capable of storing, encoding or carrying a set of instructions for execution by a processor or that cause a computer system to perform any one or more of the methods or operations disclosed herein.
- the computer-readable medium can include a solid-state memory such as a memory card or other package that houses one or more non-volatile read-only memories.
- the computer-readable medium can be a random access memory or other volatile re-writable memory.
- the computer-readable medium can include a magneto-optical or optical medium, such as a disk or tapes or other storage device to store information received via carrier wave signals such as a signal communicated over a transmission medium.
- a digital file attachment to an e-mail or other self-contained information archive or set of archives may be considered a distribution medium that is equivalent to a tangible storage medium. Accordingly, the disclosure is considered to include any one or more of a computer-readable medium or a distribution medium and other equivalents and successor media, in which data or instructions may be stored.
Landscapes
- Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Computer Security & Cryptography (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Theoretical Computer Science (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Stored Programmes (AREA)
Abstract
Description
Claims (20)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US16/896,626 US11343230B2 (en) | 2020-06-09 | 2020-06-09 | Method for configuring device resources based on network identification and system therefor |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US16/896,626 US11343230B2 (en) | 2020-06-09 | 2020-06-09 | Method for configuring device resources based on network identification and system therefor |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| US20210385193A1 US20210385193A1 (en) | 2021-12-09 |
| US11343230B2 true US11343230B2 (en) | 2022-05-24 |
Family
ID=78818048
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US16/896,626 Active US11343230B2 (en) | 2020-06-09 | 2020-06-09 | Method for configuring device resources based on network identification and system therefor |
Country Status (1)
| Country | Link |
|---|---|
| US (1) | US11343230B2 (en) |
Families Citing this family (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US11915010B2 (en) * | 2022-03-28 | 2024-02-27 | Microsoft Technology Licensing, Llc | Cross-platform multi-transport remote code activation |
| US20240414210A1 (en) * | 2023-06-09 | 2024-12-12 | Fortinet, Inc. | Systems and methods for edge processing using selectively suspended network security |
Citations (12)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20050071619A1 (en) * | 2003-09-30 | 2005-03-31 | International Business Machines Corporation | Method and system for restricting PXE servers |
| US20050283606A1 (en) * | 2004-06-22 | 2005-12-22 | Williams Mitchell A | Selecting a boot image |
| US7302698B1 (en) * | 1999-09-17 | 2007-11-27 | Hewlett-Packard Development Company, L.P. | Operation of trusted state in computing platform |
| US20100100972A1 (en) * | 2008-08-08 | 2010-04-22 | Jacques Lemieux | Approaches for a location aware client |
| US20120136979A1 (en) * | 2010-11-30 | 2012-05-31 | Wei-Chia Tseng | Method for managing distinct ip addresses in a system and related system |
| US8275895B1 (en) * | 2006-12-21 | 2012-09-25 | Crimson Corporation | Systems and methods for establishing a trusted dynamic host configuration protocol connection |
| US20160026477A1 (en) * | 2014-07-22 | 2016-01-28 | Quanta Computer Inc. | Out-of-band retrieval of network interface controller information |
| US9425978B2 (en) | 2012-06-27 | 2016-08-23 | Ubiquiti Networks, Inc. | Method and apparatus for configuring and controlling interfacing devices |
| US20190114432A1 (en) * | 2017-10-17 | 2019-04-18 | Quanta Computer Inc. | Secure environment examination |
| US20200074086A1 (en) * | 2018-08-28 | 2020-03-05 | Eclypsium, Inc. | Methods and systems for hardware and firmware security monitoring |
| US10587533B2 (en) | 2014-03-28 | 2020-03-10 | EMC IP Holding Company LLC | Facilitating management of resources |
| US20200082092A1 (en) * | 2018-09-07 | 2020-03-12 | Raytheon Company | System and method for booting processors with encrypted boot image |
-
2020
- 2020-06-09 US US16/896,626 patent/US11343230B2/en active Active
Patent Citations (12)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7302698B1 (en) * | 1999-09-17 | 2007-11-27 | Hewlett-Packard Development Company, L.P. | Operation of trusted state in computing platform |
| US20050071619A1 (en) * | 2003-09-30 | 2005-03-31 | International Business Machines Corporation | Method and system for restricting PXE servers |
| US20050283606A1 (en) * | 2004-06-22 | 2005-12-22 | Williams Mitchell A | Selecting a boot image |
| US8275895B1 (en) * | 2006-12-21 | 2012-09-25 | Crimson Corporation | Systems and methods for establishing a trusted dynamic host configuration protocol connection |
| US20100100972A1 (en) * | 2008-08-08 | 2010-04-22 | Jacques Lemieux | Approaches for a location aware client |
| US20120136979A1 (en) * | 2010-11-30 | 2012-05-31 | Wei-Chia Tseng | Method for managing distinct ip addresses in a system and related system |
| US9425978B2 (en) | 2012-06-27 | 2016-08-23 | Ubiquiti Networks, Inc. | Method and apparatus for configuring and controlling interfacing devices |
| US10587533B2 (en) | 2014-03-28 | 2020-03-10 | EMC IP Holding Company LLC | Facilitating management of resources |
| US20160026477A1 (en) * | 2014-07-22 | 2016-01-28 | Quanta Computer Inc. | Out-of-band retrieval of network interface controller information |
| US20190114432A1 (en) * | 2017-10-17 | 2019-04-18 | Quanta Computer Inc. | Secure environment examination |
| US20200074086A1 (en) * | 2018-08-28 | 2020-03-05 | Eclypsium, Inc. | Methods and systems for hardware and firmware security monitoring |
| US20200082092A1 (en) * | 2018-09-07 | 2020-03-12 | Raytheon Company | System and method for booting processors with encrypted boot image |
Also Published As
| Publication number | Publication date |
|---|---|
| US20210385193A1 (en) | 2021-12-09 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11003780B2 (en) | Method and apparatus for validating BIOS firmware using a baseboard management controller | |
| US11126725B2 (en) | Secure firmware capsule update using NVMe storage and method therefor | |
| US11320990B2 (en) | NVDIMM serial interface for out-of-band management by a baseboard management controller and method therefor | |
| US10776492B2 (en) | Multi-stage firmware update method and system therefor | |
| US10754955B2 (en) | Authenticating a boot path update | |
| US8402262B2 (en) | Enabling a heterogeneous blade environment | |
| US10860307B2 (en) | Fragmented firmware storage system and method therefor | |
| US9817975B2 (en) | Method for logging firmware attack event and system therefor | |
| US9846640B2 (en) | System and method for retrieving wireless access point credentials from a BIOS NVRAM | |
| US11989305B2 (en) | Automated update of a customized secure boot policy | |
| US11500994B2 (en) | Communication system personality provisioning system | |
| EP1960933A1 (en) | System and method for detecting unauthorized boots | |
| US20160253501A1 (en) | Method for Detecting a Unified Extensible Firmware Interface Protocol Reload Attack and System Therefor | |
| US10691448B2 (en) | Method and apparatus to execute BIOS firmware before committing to flash memory | |
| US12321459B2 (en) | Automated update of a customized secure boot policy | |
| US11343230B2 (en) | Method for configuring device resources based on network identification and system therefor | |
| US11922174B2 (en) | Management controller requests in a UEFI pre-boot environment of an information handling system | |
| US11340796B2 (en) | Method for managing sleep mode at a data storage device and system therefor | |
| US11675635B2 (en) | System and method for power management for a universal serial bus type C device used by virtualized and containerized applications | |
| US20220318430A1 (en) | Client authorization mechanisms to access native services | |
| US12541611B2 (en) | System partition security assurance to protect system boot artifacts | |
| US20250328621A1 (en) | Remote secure boot verification service for secure deployment of virtual machines | |
| US11196832B2 (en) | System and method for providing UEFI protocol access control | |
| US12307232B2 (en) | Granular lockdown of operating system based firmware updates | |
| US20240143814A1 (en) | Dynamic and secure access to uefi services based on indicator of attack driver |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| AS | Assignment |
Owner name: DELL PRODUCTS, LP, TEXAS Free format text: ASSIGNMENT OF ASSIGNORS INTEREST;ASSIGNORS:SAYYED, IBRAHIM;HAMLIN, DANIEL L.;SIGNING DATES FROM 20200528 TO 20200529;REEL/FRAME:052881/0208 |
|
| FEPP | Fee payment procedure |
Free format text: ENTITY STATUS SET TO UNDISCOUNTED (ORIGINAL EVENT CODE: BIG.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITY |
|
| AS | Assignment |
Owner name: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, NORTH CAROLINA Free format text: SECURITY AGREEMENT;ASSIGNORS:DELL PRODUCTS L.P.;EMC IP HOLDING COMPANY LLC;REEL/FRAME:053531/0108 Effective date: 20200818 |
|
| AS | Assignment |
Owner name: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT, TEXAS Free format text: SECURITY INTEREST;ASSIGNORS:DELL PRODUCTS L.P.;EMC IP HOLDING COMPANY LLC;REEL/FRAME:053578/0183 Effective date: 20200817 Owner name: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT, TEXAS Free format text: SECURITY INTEREST;ASSIGNORS:DELL PRODUCTS L.P.;EMC IP HOLDING COMPANY LLC;REEL/FRAME:053574/0221 Effective date: 20200817 Owner name: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT, TEXAS Free format text: SECURITY INTEREST;ASSIGNORS:DELL PRODUCTS L.P.;EMC IP HOLDING COMPANY LLC;REEL/FRAME:053573/0535 Effective date: 20200817 |
|
| STPP | Information on status: patent application and granting procedure in general |
Free format text: RESPONSE TO NON-FINAL OFFICE ACTION ENTERED AND FORWARDED TO EXAMINER |
|
| AS | Assignment |
Owner name: EMC IP HOLDING COMPANY LLC, TEXAS Free format text: RELEASE OF SECURITY INTEREST AT REEL 053531 FRAME 0108;ASSIGNOR:CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH;REEL/FRAME:058001/0371 Effective date: 20211101 Owner name: DELL PRODUCTS L.P., TEXAS Free format text: RELEASE OF SECURITY INTEREST AT REEL 053531 FRAME 0108;ASSIGNOR:CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH;REEL/FRAME:058001/0371 Effective date: 20211101 |
|
| STPP | Information on status: patent application and granting procedure in general |
Free format text: NOTICE OF ALLOWANCE MAILED -- APPLICATION RECEIVED IN OFFICE OF PUBLICATIONS |
|
| STPP | Information on status: patent application and granting procedure in general |
Free format text: PUBLICATIONS -- ISSUE FEE PAYMENT VERIFIED |
|
| STCF | Information on status: patent grant |
Free format text: PATENTED CASE |
|
| AS | Assignment |
Owner name: EMC IP HOLDING COMPANY LLC, TEXAS Free format text: RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053574/0221);ASSIGNOR:THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT;REEL/FRAME:060333/0001 Effective date: 20220329 Owner name: DELL PRODUCTS L.P., TEXAS Free format text: RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053574/0221);ASSIGNOR:THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT;REEL/FRAME:060333/0001 Effective date: 20220329 Owner name: EMC IP HOLDING COMPANY LLC, TEXAS Free format text: RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053578/0183);ASSIGNOR:THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT;REEL/FRAME:060332/0864 Effective date: 20220329 Owner name: DELL PRODUCTS L.P., TEXAS Free format text: RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053578/0183);ASSIGNOR:THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT;REEL/FRAME:060332/0864 Effective date: 20220329 Owner name: EMC IP HOLDING COMPANY LLC, TEXAS Free format text: RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053573/0535);ASSIGNOR:THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT;REEL/FRAME:060333/0106 Effective date: 20220329 Owner name: DELL PRODUCTS L.P., TEXAS Free format text: RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053573/0535);ASSIGNOR:THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT;REEL/FRAME:060333/0106 Effective date: 20220329 |
|
| MAFP | Maintenance fee payment |
Free format text: PAYMENT OF MAINTENANCE FEE, 4TH YEAR, LARGE ENTITY (ORIGINAL EVENT CODE: M1551); ENTITY STATUS OF PATENT OWNER: LARGE ENTITY Year of fee payment: 4 |